PT-2025-12024 · Dask · Dask

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-10096

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dask versions <=2024.8.2
Description The issue concerns a vulnerability in the Dask Distributed Server. It allows attackers to craft malicious objects using pickle serialization. These objects can be serialized on the client side and sent to the server for deserialization, potentially leading to remote command execution and granting full control over the Dask server.
Recommendations For Dask versions <=2024.8.2, consider avoiding the use of pickle serialization until a patch is available. As a temporary workaround, restrict access to the Dask Distributed Server to minimize the risk of exploitation.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10096
GHSA-XQGJ-R6XV-9CW4

Affected Products

Dask